This document lists the changes for the patch versions of the Google Kubernetes Engine (GKE) 1.36 minor version.
These changelogs are supplementary information about the updates to specific GKE system components. For information about features, changes, and security issues in GKE, see the following documents:
- Product updates: GKE release notes
- Security vulnerabilities: Security bulletins
1.36.4-gke.1495000
The following sections describe changes in this patch version when compared with the previous patch version, 1.36.4-gke.1391000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.4 changelog.
Kubernetes Updates
k8s-api
Updated k8s-api cohort from version 1.36.4-gke.200 to 1.36.4-gke.400.
- Miscellaneous:
- Updated the Go runtime and container base images for the 1.36 branch.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
clouddns
Updated clouddns component from version 36.3.3 to 36.3.5.
- Bug Fixes:
- Cloud DNS Controller: Improved shutdown logic for Cloud DNS controllers in multi-tenant environments. This ensures reconcilers, updaters, and informers are properly cleaned up when a controller shuts down, preventing resource leaks. (Fixes )
filestorecsi
Updated filestorecsi component from version 1.36.19 to 1.36.20.
- Security Fixes:
- Updated Go dependencies
google.golang.org/grpcandgolang.org/x/cryptoto resolve CVE-2026-84304 and CVE-2026-78662.
- Updated Go dependencies
gcp-controller-manager-combined
Updated gcp-controller-manager-combined component from version 36.2.0 to 36.2.3.
- Features:
- Added support in nodeannotator to populate TPU partition topology labels for TPU8i.
- Security Fixes:
- Updated github.com/google/cel-go to v0.29.2 to address security vulnerability GHSA-gcjh-h69q-9w9g.
- Miscellaneous:
- Updated the flag name for custom signer name delegation to
allow-signing-kubelet-serving-for-non-gcp. - Updated the configuration flag for custom signerName delegation to
allow-signing-kubelet-serving-for-non-gcp. - Updated the
gcp-controller-managercontainer image.
- Updated the flag name for custom signer name delegation to
gcsfusecsi
Updated gcsfusecsi component from version 1.36.42 to 1.36.43.
- Security Fixes:
- Updated Go modules, base images, and the
csi-node-driver-registrarcomponent to address security vulnerabilities.
- Updated Go modules, base images, and the
- Miscellaneous:
- Updated Go runtime to version 1.27.1.
gke-metrics-agent
Updated gke-metrics-agent component from version 2.136.20-gke.1 to 2.136.20-gke.3.
- Features:
- Implemented node-daemon Pressure Stall Information (PSI) collection.
- Added support for Pressure Stall Information (PSI) collection for node daemons.
- Miscellaneous:
- Optimized the container image size by refining vendor dependency management following Prometheus upgrades.
- Updated configuration to include Starlark options files.
- Updated Workload Autoscaler to version 0.27.0-gke.18.
gvisor
Updated gvisor component from version 1.36.23 to 1.36.24.
- Miscellaneous:
- Updated the container base image.
kube-controller-manager
Updated kube-controller-manager component from version 8.1.0 to 8.1.3.
- Miscellaneous:
- Updated configuration to include the
options.starStarlark file.
- Updated configuration to include the
kubedns
Updated kubedns component from version 36.0.3 to 36.0.5.
- Features:
- Added configuration support for automating KubeDNS cluster IP calculation for single-stack IPv6 and IPv4 clusters.
- Bug Fixes:
- Refined memory request and limit logic to scale dynamically based on the DNS engine type and control plane node size.
- Security Fixes:
- Updated Go dependencies (including golang.org/x/text, golang.org/x/net, and quic-go) and the container base image to resolve vulnerabilities: CVE-2026-56852, CVE-2026-46600, CVE-2026-42507, CVE-2026-27145, CVE-2026-42504, and CVE-2026-40898.
- Miscellaneous:
- Introduced a migration guard for Autopilot clusters utilizing Cloud DNS at cluster scope with Dataplane V2.
- Updated component options to include imports for monitoring endpoints and project-specific metadata.
managed-opentelemetry
Updated managed-opentelemetry component from version 1.36.21-gke.2 to 1.36.21-gke.3.
- Miscellaneous:
- Updated the custom OpenTelemetry collector image to version 0.153.0-gke.5.
networkpolicy-calico
Updated networkpolicy-calico component from version 4.36.1 to 4.36.2.
- Security Fixes:
- Updated the Go runtime to v1.25.12 and the golang.org/x/crypto module to v0.52.0 to resolve CVE-2026-39822.
nodelocaldns
Updated nodelocaldns component from version 36.1.2 to 36.1.5.
- Security Fixes:
- Updated Go modules to address security vulnerabilities.
pdcsi
Updated pdcsi component from version 1.36.24 to 1.36.25.
- Security Fixes:
- Updated Go modules, the Go runtime, and container base images to address security vulnerabilities across the Persistent Disk CSI driver and its sidecar components, including csi-resizer, csi-snapshotter, csi-provisioner, and csi-attacher.
tpu-device-plugin
Updated tpu-device-plugin component from version 1.36.7-gke.1 to 1.36.9-gke.0.
- Features:
- Update ACS Agent image to include FatalErrorInfo and TPU Halt diagnostic collection.
- Introduce TPU baremetal node support via
--enable-baremetal-mode. - Skip MDS partition topology label polling for TPU8i (populated by cloud-provider-gcp).
- Add multislice network, compute and transfer size/latency metrics.
- Support enable_full_hierarchy_labels KCP trait.
- Move ACS Agent (
acs-agent) container fromtpu-device-pluginDaemonSet toai-telemetry-collectorDaemonSet to prevent guest diagnostic telemetry failures from impacting device plugin health and scheduling availability.
- Bug Fixes:
- Add bounds checks for bucket count in TPU device plugin metrics.
- Restore vbar.sock permission-change log.
- Revert ACS Agent image to sha256:2c2cad2eff5811c906334bced6a00b6f938d4308a26921bab9f5fc7d7ef445fb to prevent synchronous informer cache sync stalls from blocking TPU device plugin registration and unblock Cluster Autoscaler qualification.
- Security Fixes:
- Updated
google.golang.org/grpcto version 1.82.1 to address security vulnerability GO-2026-6061. - Block vbar.sock symlink privilege escalation by mounting vbar directory read-only into workloads and enforcing safeChmod.
- Updated runtime base image to
gcr.io/distroless/static-debian13and builder to Golang 1.27.0 to fix base image vulnerabilities.
- Updated
- Miscellaneous:
- Updated the
gke-distroless/bashbase image.
- Updated the
workloadautoscaler
Updated workloadautoscaler component from version 19.11.0 to 19.14.0.
- Miscellaneous:
- Updated Vertical Pod Autoscaler components (admission-controller, recommender, and updater) and the autoscaling-metrics-adapter to version 0.27.0-gke.19.
1.36.4-gke.1391000
The following sections describe changes in this patch version when compared with the previous patch version, 1.36.4-gke.1247000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.4 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
customer-logs-exporter
Updated customer-logs-exporter component from version 1.36.0-gke.11 to 1.36.0-gke.12.
- Security Fixes:
- Updated google.golang.org/grpc to v1.82.1 to resolve security advisory GO-2026-6061.
filestorecsi
Updated filestorecsi component from version 1.36.17 to 1.36.19.
- Miscellaneous:
- Updated the Go runtime to version 1.25.11 and refreshed container base images for csi-provisioner, csi-resizer, csi-snapshotter, snapshot-controller, and snapshot-validation-webhook.
- Updated base images to the latest distroless versions for improved security and stability.
- Explicitly named an internal initialization container as
imgSpnpInitContainerin the component manifest.
gcsfusecsi
Updated gcsfusecsi component from version 1.36.41 to 1.36.42.
- Miscellaneous:
- Updated the Go runtime to version 1.27.1 and updated container images for the CSI driver, node driver registrar, sidecar mounter, webhook, and metadata prefetcher.
gpu-device-plugin
Updated gpu-device-plugin component from version 1.36.3-gke.2 to 1.36.5-gke.3.
- Miscellaneous:
- bump
gpu-device-plugintov1.36.4-gke.0 - bump
nvidia-partition-gputov1.36.4-gke.0 - bump
nvidia-persistenced-installertov1.36.4-gke.0 - Updated the
gpu-fraction-divisorpath to use underscores instead of hyphens.
- bump
kube-addon-manager
Updated kube-addon-manager component from version 35.0.2 to 35.0.5.
- Features:
- Added support for multi-architecture releases.
- Miscellaneous:
- Updated the kubectl prune whitelist to include flow control resources (FlowSchema and PriorityLevelConfiguration) for clusters running Kubernetes 1.23.0 and newer.
- Added a configuration option to manage leader election modes for the addon manager.
pdcsi
Updated pdcsi component from version 1.36.23 to 1.36.24.
- Security Fixes:
- Updated Go modules to resolve CVE-2026-46600, CVE-2026-56852, CVE-2026-29181, and CVE-2026-39883.
- Miscellaneous:
- Updated the Go runtime to version 1.26.5.
- Updated the
debian-baseanddistroless-staticcontainer base images for the CSI driver, snapshotter, and related sidecar components.
1.36.4-gke.1247000
The following sections describe changes in this patch version when compared with the previous patch version, 1.36.4-gke.1082000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.4 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
gcp-controller-manager-combined
Updated gcp-controller-manager-combined component from version 36.1.4 to 36.2.0.
- Features:
- Added support for the
ToLocalhosttype within the component configuration. - Added the
--fetched_cert_validityflag to allow configuration of certificate TTL for fetched credentials.
- Added support for the
- Miscellaneous:
- Renamed the custom signerName delegation flag to
allow-signing-kubelet-serving-for-non-gcpto improve clarity for signing kubelet serving certificates on non-GCP nodes. - Removed legacy host-path volume mounts for
/etc/srv/kubernetes/pkiand associated command-line flags for cluster CA files (--cluster-root-ca-fileand--cluster-ca-bundle) in favor of DCD.
- Renamed the custom signerName delegation flag to
gke-metrics-agent
Updated gke-metrics-agent component from version 2.136.20-gke.0 to 2.136.20-gke.1.
- Features:
- Implemented Pressure Stall Information (PSI) collection for node daemons.
- Miscellaneous:
- Reduced the container image size by optimizing vendor dependency trimming.
l7-lb-controller-combined
Updated l7-lb-controller-combined component from version 1.41.3-gke.0 to 1.41.4-gke.0.
- Features:
- Added support for BYOIPv6 NetLB via the
ip-collection-v6annotation.
- Added support for BYOIPv6 NetLB via the
- Bug Fixes:
- Improved Standalone NEG LB controller with better event messaging, rule sorting, IP sanitization, and user error classification (including BackendNotAttached condition).
- Allowed static BYOIPv6 addresses without the
ip-collection-v6annotation, and added a warning when the annotation is mistakenly used on an ILB. - Refactored L4 standalone NEG controller logic.
- Security Fixes:
- Addressed a Confused Deputy vulnerability in the Standalone NEG controller by verifying that service NEGs are attached to the LB backend service before writing the LB VIP into the service status.
osimage
Updated osimage component from version 1.36.95 to 1.36.99.
- Security Fixes:
- Fixed vulnerabilities in the Linux kernel: CVE-2026-68293.
- Updated dev-libs/libxml2 to v2.15.3 to resolve CVE-2026-0989, CVE-2026-0990, and CVE-2026-0992.
- Miscellaneous:
- Updated system packages and dependencies: containerd and containerd-test to v2.2.7, fluent-bit to v4.2.8, unzip to v6.0_p31, dash to v0.5.13.5, libverto to v0.3.2-r1, popt to v1.19-r1, acl to v2.4.0-r2, and passwdqc to v2.0.3-r1.
- Adjusted runtime sysctl configuration for net.ipv4.udp_mem.
1.36.4-gke.1082000
The following sections describe changes in this patch version when compared with the previous patch version, 1.36.3-gke.1767000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.4 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
customer-logs-exporter
Updated customer-logs-exporter component from version 1.36.0-gke.9 to 1.36.0-gke.11.
- Security Fixes:
- Updated
google.golang.org/grpcto v1.82.1 to resolve GO-2026-6061.
- Updated
- Miscellaneous:
- Introduced new configuration support for cloud logging endpoints and project-specific metadata via
ComponentOptionsConfig.
- Introduced new configuration support for cloud logging endpoints and project-specific metadata via
gke-metrics-agent
Updated gke-metrics-agent component from version 2.136.18-gke.1 to 2.136.20-gke.0.
- Features:
- Implemented node-level Pressure Stall Information (PSI) collection.
- Miscellaneous:
- Optimized the container image size by adjusting vendor dependencies, reducing the image size from approximately 64MB to 47MB.
- Updated Workload Autoscaler to version 0.27.0-gke.17.
gvisor
Updated gvisor component from version 1.36.19 to 1.36.23.
- Miscellaneous:
- Updated gVisor to version 20260727.0_RC04.
l7-lb-controller-combined
Updated l7-lb-controller-combined component from version 1.41.1-gke.0 to 1.41.3-gke.0.
- Bug Fixes:
- Improved L4 Address Manager IP validation to prevent false positive substring matches and enforce explicit Network Tier and Load Balancing Scheme validation.
- Security Fixes:
- Go version update to 1.26.6, Go kubernetes client dependency updates to v1.36.3, update google.golang.org/api and google.golang.org/grpc to the newest versions.
osimage
Updated osimage component from version 1.36.75 to 1.36.95.
- Features:
- cchost: Added
bpf-lsm-policyfor enhanced VM restrictions. - Enabled CONFIG_UDMABUF on x86_64.
- Added support for net-fs/lustre-client-drivers v2.14.0_p259.
- Updated Linux kernel to COS-6.12.94.
- Updated Docker to v27.5.1.
- Updated Containerd to v2.2.6.
- Updated cos-gpu-installer to v2.7.7.
- cchost: Added
- Bug Fixes:
- Added a kernel patch to reduce the bcache garbage collection sleep interval, which prevents potential I/O stalls.
- Upgraded sys-apps/xemu to v0.0.10.
- Security Fixes:
- Fixed CVE-2026-64244, CVE-2026-64247, CVE-2026-64253, CVE-2026-64265, CVE-2026-64266, CVE-2026-64284, CVE-2026-64289, CVE-2026-64294, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64313, CVE-2026-64317, CVE-2026-64319, CVE-2026-64320, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64326, CVE-2026-64354, CVE-2026-64355, CVE-2026-64357, CVE-2026-64368, CVE-2026-64370, CVE-2026-64373, CVE-2026-64378, CVE-2026-64379, CVE-2026-64380, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64411, CVE-2026-64412, CVE-2026-64414, CVE-2026-64415, CVE-2026-64418, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64432, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64456, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475, CVE-2026-64512, CVE-2026-64514, and CVE-2026-64556 in the Linux kernel.
- Fixed CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, and CVE-2026-46598 in dev-go/crypto.
- Fixed CVE-2026-58055 by upgrading net-libs/nghttp2 to 1.69.0.
- Fixed CVE-2026-58470 in net-misc/wget.
- Fixed CVE-2026-59890 in dev-python/setuptools.
- Fixed CVE-2026-33186 in google-guest-agent.
- Fixed CVE-2026-64227 in the Linux kernel.
- Fixed CVE-2026-64279 in the Linux kernel.
- Fixed CVE-2026-64286 in the Linux kernel.
- Fixed CVE-2026-64287 in the Linux kernel.
- Fixed CVE-2026-64352 in the Linux kernel.
- Fixed CVE-2026-64375 in the Linux kernel.
- Fixed CVE-2026-64401 in the Linux kernel.
- Fixed CVE-2026-64413 in the Linux kernel.
- Fixed CVE-2026-64416 in the Linux kernel.
- Fixed CVE-2026-64476 in the Linux kernel.
- Fixed CVE-2026-64508 in the Linux kernel.
- Fixed CVE-2026-64530 in the Linux kernel.
- Fixed CVE-2026-64532 in the Linux kernel.
- Fixed CVE-2026-64533 in the Linux kernel.
- Fixed CVE-2026-64534 in the Linux kernel.
- Fixed CVE-2026-64535 in the Linux kernel.
- Fixed CVE-2026-64538 in the Linux kernel.
- Fixed CVE-2026-64542 in the Linux kernel.
- Fixed CVE-2026-64545 in the Linux kernel.
- Fixed CVE-2026-64546 in the Linux kernel.
- Fixed CVE-2026-64548 in the Linux kernel.
- Fixed CVE-2026-64552 in the Linux kernel.
- Fixed CVE-2026-64554 in the Linux kernel.
- Fixed CVE-2026-64555 in the Linux kernel.
- Fixed KCTF-8173f7e in the Linux kernel.
- Fixed CVE-2026-64561 in the Linux kernel.
- Fixed CVE-2026-64562 in the Linux kernel.
- Fixed CVE-2026-64567 in the Linux kernel.
- Fixed CVE-2026-64572 in the Linux kernel.
- Fixed CVE-2026-64576 in the Linux kernel.
- Fixed CVE-2026-64579 in the Linux kernel.
- Fixed CVE-2026-64590 in the Linux kernel.
- Fixed CVE-2026-64593 in the Linux kernel.
- Fixed CVE-2026-64597 in the Linux kernel.
- Fixed CVE-2026-64598 in the Linux kernel.
- Fixed CVE-2026-64604 in the Linux kernel.
- Fixed CVE-2026-68092 in the Linux kernel.
- Fixed CVE-2026-68093 in the Linux kernel.
- Fixed CVE-2026-68116 in the Linux kernel.
- Fixed CVE-2026-68119 in the Linux kernel.
- Fixed CVE-2026-68136 in the Linux kernel.
- Fixed CVE-2026-68139 in the Linux kernel.
- Fixed CVE-2026-68142 in the Linux kernel.
- Fixed CVE-2026-68145 in the Linux kernel.
- Fixed CVE-2026-68147 in the Linux kernel.
- Fixed CVE-2026-68149 in the Linux kernel.
- Fixed CVE-2026-68171 in the Linux kernel.
- Fixed CVE-2026-68184 in the Linux kernel.
- Fixed CVE-2026-68186 in the Linux kernel.
- Fixed CVE-2026-68187 in the Linux kernel.
- Fixed CVE-2026-68296 in the Linux kernel.
- Fixed CVE-2026-68299 in the Linux kernel.
- Fixed CVE-2026-68329 in the Linux kernel.
- Fixed CVE-2026-68336 in the Linux kernel.
- Fixed CVE-2026-68343 in the Linux kernel.
- Fixed CVE-2026-68386 in the Linux kernel.
- Fixed CVE-2026-68388 in the Linux kernel.
- Fixed CVE-2026-68396 in the Linux kernel.
- Fixed CVE-2026-68425 in the Linux kernel.
- Fixed CVE-2026-68428 in the Linux kernel.
- Fixed CVE-2026-68432 in the Linux kernel.
- Fixed CVE-2026-68442 in the Linux kernel.
- Fixed CVE-2026-68450 in the Linux kernel.
- Fixed CVE-2026-68284 in the Linux kernel.
- Fixed CVE-2026-68398 in the Linux kernel.
- Fixed CVE-2026-68096 in the Linux kernel.
- Fixed CVE-2026-68129 in the Linux kernel.
- Fixed CVE-2026-68146 in the Linux kernel.
- Fixed CVE-2026-68325 in the Linux kernel.
- Fixed CVE-2026-68338 in the Linux kernel.
- Fixed CVE-2026-68422 in the Linux kernel.
- Fixed KCTF-0650f1c in the Linux kernel.
- Miscellaneous:
- Adjusted runtime sysctl configuration for
net.ipv4.udp_mem. - Adjusted runtime sysctl
net.ipv4.udp_memsettings to optimize memory thresholds for UDP networking.
- Adjusted runtime sysctl configuration for
1.36.3-gke.1767000
The following sections describe changes in this patch version when compared with the previous patch version, 1.36.3-gke.1640000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.3 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
clouddns
Updated clouddns component from version 36.3.2 to 36.3.3.
- Bug Fixes:
- Fix crash loop by mounting tmp as read-write in clouddns container.
gcsfusecsi
Updated gcsfusecsi component from version 1.36.38 to 1.36.41.
- Security Fixes:
- Updated
golang.org/x/modfrom v0.37.0 to v0.40.0 to address security vulnerability GO-2026-6179.
- Updated
networkpolicy-calico
Updated networkpolicy-calico component from version 4.36.0 to 4.36.1.
- Security Fixes:
- Fixed CVE-2026-39822 by updating the Go build version to 1.25.12.
- Updated
golang.org/x/cryptoto v0.52.0 to remediate security vulnerabilities in the Calico node component.